First published: Tue Mar 24 2009(Updated: )
IBM Rational AppScan Enterprise before 5.5 FP1 allows remote attackers to read arbitrary exported reports by "forcefully browsing."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational AppScan | <=5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1056 is considered a medium severity vulnerability as it allows remote attackers to access sensitive reports.
To fix CVE-2009-1056, upgrade IBM Rational AppScan Enterprise to version 5.5 FP1 or later.
IBM Rational AppScan Enterprise versions prior to 5.5 FP1 are affected by CVE-2009-1056.
CVE-2009-1056 allows attackers to read arbitrary exported reports through forceful browsing techniques.
Currently, the recommended solution for CVE-2009-1056 is to update to a secure version rather than rely on a workaround.